[Help] 2 Wordpress websites got hacked from 1 Bluehost account

Vincenzo Udinesi

Junior Member
Joined
Jan 14, 2019
Messages
186
Reaction score
63
Hi all the great people out there,

2 out of my 5 websites on a single Bluehost account have been hacked yesterday and I am not able to figure out how to stop this from happening again.

The hacked websites are the only sites with some traffic so I doubt that the hacker did not touch other sites intentionally as it was of no value to him.

Yesterday I received an email from Google Search Console Team saying "Social engineering content detected on https://www.mysite1.com"

I visited website(with a vpn) to see what was going on and there was a Chinese(or some other Asian) language website being loaded instead of my homepage, I visited other post pages and they were all fine.

Today, I received another email from Google Search Console Team saying "Google has identified that [email protected](original email) has been added as an owner of https://mysite2.com" I am the only owner and when I logged into Search Console, I could not see any other owner(may be the hacker deleted himself).

I contacted Bluehost and they scanned my account for malware, later they emailed me a malware.txt file which contains a list of 23 infected files: 21 files are php and 2 are .htaccess.

Hosting company suspended my account temporarily.

Now, how should I go about it?

Deleting those 2 Wordpress installations inside hosting account and reinstalling from backups would be enough?

  • Both websites have very popular themes and some 5-6 plugins like Yoast etc.
  • Wordpress versions were regularly updated.
  • No nulled themes, plugins were used.

Please guide me about what measures to take, thank you for in advance :)
 
This happened to me like 2minths ago, but I figured that it was caused by a malware in one of my themes. I was frustrated that I deleted the whole of my WordPress after backing up my post and pages.

The malware was in Japanese, an auto generated pages of over 30k pages.

What I did
After reinstalling my WordPress and my backup. I changed theme, I make sure I scan with virus total to be sure it's free. I scan every theme and plugin I use with virus total to be safe.

I deindex all affected pages from google search console.
I am just recovering.

You may have been infected by a backdoor malware in one of your themes or plugin you didn't know about. That gave access to the hacker to party all night.
 
This happened to me like 2minths ago, but I figured that it was caused by a malware in one of my themes. I was frustrated that I deleted the whole of my WordPress after backing up my post and pages.

The malware was in Japanese, an auto generated pages of over 30k pages.

What I did
After reinstalling my WordPress and my backup. I changed theme, I make sure I scan with virus total to be sure it's free. I scan every theme and plugin I use with virus total to be safe.

I deindex all affected pages from google search console.
I am just recovering.

You may have been infected by a backdoor malware in one of your themes or plugin you didn't know about. That gave access to the hacker to party all night.


Thank you for for the help, the two websites under attack use different themes.
Is it possible that the hacker entered from one theme and was able to infect the other site on the same hosting account?

Also, by reinstalling WordPress you mean deleting the whole website in Bluehost(or any other hosting) and creating a new WordPress installation from scratch?

Thank you for the support.
 
Yes of course as at the time my site got hacked on a shared hosting with namecheap, 3 other of my sites were also infected. That's one of the disadvantages of shared hosting because from one site you would get access to another.

You can scan your website and remove the infected page or use wordfence plugin to do that and secure your site for future threat. It's not free though. I think someone shared the null version here few weeks ago.

But what I did was backup my site content, deleted the entire WordPress site and reinstall WordPress. I did this just to be sure I was no longer infected by the virus.

After cleaning You can enter the address of your site say www.example.com/xxxxxxxc
The xxx is the pages infected if it still loads a scam page or Japanese then you still have the malware in you site. But if otherwise showing 404 error then you are safe.

You can then proceed to deindex the hacked pages on you website which were already index.

This hackers have special code in indexing this pages faster.

Thank you for for the help, the two websites under attack use different themes.
Is it possible that the hacker entered from one theme and was able to infect the other site on the same hosting account?

Also, by reinstalling WordPress you mean deleting the whole website in Bluehost(or any other hosting) and creating a new WordPress installation from scratch?

Thank you for the support.
 
Download wordfence and configure it well. Which version yoast are you using free or premium one

I will definitely install Wordfence as the other forum member has recommended too the same plugin.

I'm using the Yoast free version.

P.S: I just downloaded my whole website from FTP and the infected file was identified by Windows Defender as Backdoor:PHP/Chopper.B!dha.
 
Back
Top